Home / Companies / Detectify / Blog / March 2023

March 2023 Summaries

4 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
Developers are increasingly releasing updates more frequently, prompting AppSec teams to prioritize and remediate threats more effectively. Despite the availability of various tools, no single solution comprehensively addresses all the challenges faced by AppSec teams, particularly as modern tech architecture blurs application boundaries. Common obstacles include the overwhelming number of vulnerabilities and outdated prioritization systems like CVE/CVSS, which fail to consider the complexities of today’s software built with microservices and APIs. As AppSec teams collaborate with developers to accelerate remediation of critical threats, External Attack Surface Management (EASM) solutions are emerging as valuable tools, offering a more holistic approach by identifying unknown Internet-facing assets and reducing cognitive overload.
Mar 28, 2023 881 words in the original blog post.
Detectify emphasizes an AppSec perspective by focusing on how both AppSec teams and developers experience their platform, acknowledging the pressure developers face to quickly release new code while meeting business demands. This has led to increased reliance on automation in AppSec tooling, with a shift towards more frequent software releases by development teams, particularly in SaaS companies, to deliver customer value faster. Shorter release cycles allow developers to demonstrate the impact of new features but also necessitate accepting higher risks, potentially causing internal friction and delayed customer value. AppSec teams are encouraged to prioritize remediation speed over reducing the number of vulnerabilities, as faster remediation indicates a more effective security program. This approach involves a layered security testing strategy, shifting both left and right, to continuously assess risks in both staging and production environments, moving away from aiming for zero vulnerabilities to resolving severe threats through prioritization and accountability. Detectify's e-book discusses how External Attack Surface Management (EASM) can help AppSec teams better prioritize and remediate threats, addressing challenges with traditional tools and improving collaboration between security and development teams.
Mar 17, 2023 708 words in the original blog post.
Detectify has introduced an updated Vulnerabilities page designed to help security teams more efficiently manage and remediate vulnerabilities by providing a comprehensive overview of their attack surfaces. This new page allows users to view, sort, filter, and export vulnerability data, making it easier to focus on high and critical severity issues affecting business-critical applications, while also enabling the suppression of non-threatening findings. The update includes several enhancements and fixes, such as resolving issues with the AWS connector, adding scan profile and host filters to the API, and offering weekly scanning configuration options. Users can access a demo of the new features and explore detailed documentation in the knowledge base. Additionally, the platform now includes new vulnerabilities sourced from the ethical hacker community, offering insights into recent threats like improper access checks, remote code execution (RCE) vulnerabilities, and cross-site scripting (XSS) exposures.
Mar 16, 2023 533 words in the original blog post.
In today's complex digital landscape, organizations prioritize effective cybersecurity using various tools like EASM, CAASM, and DRPS, each serving distinct but complementary roles in securing assets. EASM, or External Attack Surface Management, focuses on identifying and managing vulnerabilities in an organization's external assets by providing visibility into Internet-facing components, while CAASM, Continuous Asset and Attack Surface Management, extends this scope to include internal assets, requiring integration with existing systems and more manual processes. DRPS, or Digital Risk Protection Services, targets digital risks affecting brand reputation and online presence by monitoring social media, websites, and the dark web for potential threats. Each technology supports different aspects of cybersecurity, with EASM being easier to deploy for external asset management, CAASM offering a comprehensive view by including internal assets, and DRPS focusing on brand and data protection. The choice between these tools depends on an organization's specific security needs and resources, with the potential for them to be used in tandem to enhance overall security posture.
Mar 08, 2023 1,550 words in the original blog post.